HashMetadataValues carries SaltLength and HashLength alongside the type and the cost parameters, and NeedsRehash ignored both. A hash with a 16-byte digest or an 8-byte salt verified fine and was judged current forever -- exactly the drift this method exists to catch. Unreachable today, since every hash ModernUO has written uses the library defaults of 32 and 16, but that is a property of the current configuration rather than of the check. The two lengths are the decoded sizes of the base64 segments rather than entries in the m/t/p list, so they cannot be varied through the existing theory template; they get their own rows with pinned literals. The "current defaults" row of that theory is the negative control. Also name the benchmark behind the 8.5 ms / 10.1 ms figures in the parameter comment: ModernUO-Benchmarks/Benchmarks/Argon2Hashing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| Application | ||
| BuildTool | ||
| Logger | ||
| Server | ||
| Server.Tests | ||
| UOContent | ||
| UOContent.Tests | ||